CVE-2024-7734

MEDIUM

Phoenixcontact TC Mguard Rs4000 4G Vz... - Resource Allocation Without Limits

Title source: rule

Description

An unauthenticated remote attacker can exploit the behavior of the pathfinder TCP encapsulation service by establishing a high number of TCP connections to the pathfinder TCP encapsulation service. The impact is limited to blocking of valid IPsec VPN peers.

Scores

CVSS v3 5.3
EPSS 0.0014
EPSS Percentile 33.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L

Classification

CWE
CWE-770
Status published

Affected Products (36)

phoenixcontact/tc_mguard_rs4000_4g_vzw_vpn_firmware < 8.9.3
phoenixcontact/tc_mguard_rs4000_4g_vpn_firmware < 8.9.3
phoenixcontact/tc_mguard_rs4000_4g_att_vpn_firmware < 8.9.3
phoenixcontact/tc_mguard_rs4000_3g_vpn_firmware < 8.9.3
phoenixcontact/tc_mguard_rs2000_4g_vzw_vpn_firmware < 8.9.3
phoenixcontact/tc_mguard_rs2000_4g_vpn_firmware < 8.9.3
phoenixcontact/tc_mguard_rs2000_4g_att_vpn_firmware < 8.9.3
phoenixcontact/tc_mguard_rs2000_3g_vpn_firmware < 8.9.3
phoenixcontact/fl_mguard_smart2_vpn_firmware < 8.9.3
phoenixcontact/fl_mguard_smart2_firmware < 8.9.3
phoenixcontact/fl_mguard_rs4004_tx\/dtx_vpn_firmware < 8.9.3
phoenixcontact/fl_mguard_rs4004_tx\/dtx_firmware < 8.9.3
phoenixcontact/fl_mguard_rs4000_tx\/tx_vpn_firmware < 8.9.3
phoenixcontact/fl_mguard_rs4000_tx\/tx-p_firmware < 8.9.3
phoenixcontact/fl_mguard_rs4000_tx\/tx-m_firmware < 8.9.3
... and 21 more

Timeline

Published Sep 10, 2024
Tracked Since Feb 18, 2026